CVE-2020-8286
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 4.6%
exploitation probability
4.6%top 9% of all CVEs
observed exploitation
nono source reports it
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
Affected products
n/a · https://github.com/curl/curlReferences
https://cert-portal.siemens.com/productcert/pdf/ssa-200951.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://curl.se/docs/CVE-2020-8286.htmlhttp://seclists.org/fulldisclosure/2021/Apr/50http://seclists.org/fulldisclosure/2021/Apr/51http://seclists.org/fulldisclosure/2021/Apr/54https://hackerone.com/reports/1048457https://lists.debian.org/debian-lts-announce/2020/12/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/https://security.gentoo.org/glsa/202012-14https://security.netapp.com/advisory/ntap-20210122-0007/